From 8b252709a45e24fa83b443af6281ac612862b05d Mon Sep 17 00:00:00 2001
From: 码上秃Hello <19973252123@163.com>
Date: Tue, 15 Aug 2023 11:25:00 +0800
Subject: [PATCH] 修改个人信息:防止用户有目的性的修改其他属性
---
ruoyi-modules/ruoyi-system/src/main/java/com/ruoyi/system/controller/SysPostController.java | 38 ++++++++++++++++++--------------------
1 files changed, 18 insertions(+), 20 deletions(-)
diff --git a/ruoyi-modules/ruoyi-system/src/main/java/com/ruoyi/system/controller/SysPostController.java b/ruoyi-modules/ruoyi-system/src/main/java/com/ruoyi/system/controller/SysPostController.java
index 15ca5b6..d1dbff1 100644
--- a/ruoyi-modules/ruoyi-system/src/main/java/com/ruoyi/system/controller/SysPostController.java
+++ b/ruoyi-modules/ruoyi-system/src/main/java/com/ruoyi/system/controller/SysPostController.java
@@ -1,6 +1,5 @@
package com.ruoyi.system.controller;
-import java.io.IOException;
import java.util.List;
import javax.servlet.http.HttpServletResponse;
import org.springframework.beans.factory.annotation.Autowired;
@@ -13,14 +12,13 @@
import org.springframework.web.bind.annotation.RequestBody;
import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RestController;
-import com.ruoyi.common.core.constant.UserConstants;
import com.ruoyi.common.core.utils.poi.ExcelUtil;
import com.ruoyi.common.core.web.controller.BaseController;
import com.ruoyi.common.core.web.domain.AjaxResult;
import com.ruoyi.common.core.web.page.TableDataInfo;
import com.ruoyi.common.log.annotation.Log;
import com.ruoyi.common.log.enums.BusinessType;
-import com.ruoyi.common.security.annotation.PreAuthorize;
+import com.ruoyi.common.security.annotation.RequiresPermissions;
import com.ruoyi.common.security.utils.SecurityUtils;
import com.ruoyi.system.domain.SysPost;
import com.ruoyi.system.service.ISysPostService;
@@ -40,7 +38,7 @@
/**
* 获取岗位列表
*/
- @PreAuthorize(hasPermi = "system:post:list")
+ @RequiresPermissions("system:post:list")
@GetMapping("/list")
public TableDataInfo list(SysPost post)
{
@@ -50,9 +48,9 @@
}
@Log(title = "岗位管理", businessType = BusinessType.EXPORT)
- @PreAuthorize(hasPermi = "system:post:export")
+ @RequiresPermissions("system:post:export")
@PostMapping("/export")
- public void export(HttpServletResponse response, SysPost post) throws IOException
+ public void export(HttpServletResponse response, SysPost post)
{
List<SysPost> list = postService.selectPostList(post);
ExcelUtil<SysPost> util = new ExcelUtil<SysPost>(SysPost.class);
@@ -62,28 +60,28 @@
/**
* 根据岗位编号获取详细信息
*/
- @PreAuthorize(hasPermi = "system:post:query")
+ @RequiresPermissions("system:post:query")
@GetMapping(value = "/{postId}")
public AjaxResult getInfo(@PathVariable Long postId)
{
- return AjaxResult.success(postService.selectPostById(postId));
+ return success(postService.selectPostById(postId));
}
/**
* 新增岗位
*/
- @PreAuthorize(hasPermi = "system:post:add")
+ @RequiresPermissions("system:post:add")
@Log(title = "岗位管理", businessType = BusinessType.INSERT)
@PostMapping
public AjaxResult add(@Validated @RequestBody SysPost post)
{
- if (UserConstants.NOT_UNIQUE.equals(postService.checkPostNameUnique(post)))
+ if (!postService.checkPostNameUnique(post))
{
- return AjaxResult.error("新增岗位'" + post.getPostName() + "'失败,岗位名称已存在");
+ return error("新增岗位'" + post.getPostName() + "'失败,岗位名称已存在");
}
- else if (UserConstants.NOT_UNIQUE.equals(postService.checkPostCodeUnique(post)))
+ else if (!postService.checkPostCodeUnique(post))
{
- return AjaxResult.error("新增岗位'" + post.getPostName() + "'失败,岗位编码已存在");
+ return error("新增岗位'" + post.getPostName() + "'失败,岗位编码已存在");
}
post.setCreateBy(SecurityUtils.getUsername());
return toAjax(postService.insertPost(post));
@@ -92,18 +90,18 @@
/**
* 修改岗位
*/
- @PreAuthorize(hasPermi = "system:post:edit")
+ @RequiresPermissions("system:post:edit")
@Log(title = "岗位管理", businessType = BusinessType.UPDATE)
@PutMapping
public AjaxResult edit(@Validated @RequestBody SysPost post)
{
- if (UserConstants.NOT_UNIQUE.equals(postService.checkPostNameUnique(post)))
+ if (!postService.checkPostNameUnique(post))
{
- return AjaxResult.error("修改岗位'" + post.getPostName() + "'失败,岗位名称已存在");
+ return error("修改岗位'" + post.getPostName() + "'失败,岗位名称已存在");
}
- else if (UserConstants.NOT_UNIQUE.equals(postService.checkPostCodeUnique(post)))
+ else if (!postService.checkPostCodeUnique(post))
{
- return AjaxResult.error("修改岗位'" + post.getPostName() + "'失败,岗位编码已存在");
+ return error("修改岗位'" + post.getPostName() + "'失败,岗位编码已存在");
}
post.setUpdateBy(SecurityUtils.getUsername());
return toAjax(postService.updatePost(post));
@@ -112,7 +110,7 @@
/**
* 删除岗位
*/
- @PreAuthorize(hasPermi = "system:post:remove")
+ @RequiresPermissions("system:post:remove")
@Log(title = "岗位管理", businessType = BusinessType.DELETE)
@DeleteMapping("/{postIds}")
public AjaxResult remove(@PathVariable Long[] postIds)
@@ -127,6 +125,6 @@
public AjaxResult optionselect()
{
List<SysPost> posts = postService.selectPostAll();
- return AjaxResult.success(posts);
+ return success(posts);
}
}
--
Gitblit v1.9.3